Trust Center

Security, privacy and compliance — verified.

Safeguarding patient data is non‑negotiable. ClinixSummary employs industry‑standard encryption, strict access controls and immediate audio deletion — governed by the ClinixQM Quality Management System — to give you confidence that your practice and your patients are protected.

verified_user
HIPAA
Ready
shield
SOC 2
Aligned
medical_services
MHRA · UKCA
Class I registered
privacy_tip
GDPR
Compliant
encrypted
AES-256
Encryption
flag
PIPEDA / PHIPA
Compliant
policy
CCPA
Compliant
domain_verification
ISO 27001
Aligned
Medical Device Regulation

Registered with the MHRA. UKCA marked.

ClinixSummary is registered with the UK Medicines and Healthcare products Regulatory Agency (MHRA) as a Class I medical device and carries UKCA marking. Clinical documentation software that meets the regulatory bar your practice is held to.

MHRA registration

Registered as a medical device with the UK regulator, with the obligations that registration carries — vigilance, traceability and post‑market surveillance.

UKCA marking

The UKCA mark declares conformity with the UK Medical Devices Regulations for a Class I device — covering safety, performance and labelling requirements.

Governed by ClinixQM

Our quality management system underpins the registration — documented processes for risk, change control, incident handling and continuous improvement.

lock

End‑to‑end encryption

All data is encrypted in transit using TLS 1.2+ and encrypted at rest with AES‑256. These bank‑grade standards ensure that voice recordings, transcripts and metadata remain confidential at all times.

cleaning_services

Ephemeral audio & data control

We never store audio recordings. Once your note is generated, recordings are immediately and permanently deleted. You remain in control of your transcripts, which you can remove at any time.

gavel

HIPAA & GDPR compliance

ClinixSummary meets the requirements of HIPAA, GDPR, PIPEDA/PHIPA, CCPA and other global privacy regulations. We sign Business Associate Agreements (BAAs) and maintain full regulatory alignment.

auto_fix

De-identified training data

Our models are fine‑tuned on anonymised, de-identified, non‑PHI data and run inference on secure infrastructure. We never use your transcripts to train customer‑facing models.

bug_report

Penetration testing

Regular third‑party penetration tests and vulnerability assessments are conducted against our infrastructure and applications. Findings are triaged, remediated and re‑tested on a continuous basis.

emergency_home

Incident response

A documented incident response plan ensures breach notification within 72 hours as required by GDPR. 24/7 monitoring, alerting and defined escalation playbooks keep response times minimal.

ClinixQM Quality Management Process

Clinix QM: Quality at every layer.

The ClinixQM Quality Management Process generates outputs that meet clinical standards through systematic review, feedback loops, and continuous improvement protocols.

fact_check

Clinical QA Reviews

Dedicated quality assurance team conducts regular manual reviews of model outputs against clinical documentation standards, ensuring accuracy and completeness.

admin_panel_settings

Role-Based Access Controls

Fine-grained permission systems ensure that only authorised personnel can access patient data, with full audit trails for every action taken in the system.

verified

Compliance Certifications

Ongoing certification processes and third-party audits ensure ClinixSummary meets and exceeds healthcare industry security and compliance benchmarks.

Sub-Processor Transparency

Our vendors, disclosed.

We believe in full transparency about the third parties that help us deliver our service. Every sub-processor is bound by data protection obligations no less protective than our own. We provide at least 30 days' written notice before engaging a new sub-processor.

Sub-Processor Purpose Data Processed Location
OpenAITranscript and speech inference for clinical contextDe-identified clinical textUSA
Anthropic (Claude)Security & live system monitoringSystem logs & operational telemetry (no PHI)USA
Google (GCP)Cloud infrastructureEncrypted clinical dataMulti-region
Microsoft AzureCloud infrastructure, AI services & speech-to-textEncrypted clinical dataMulti-region
StripePayment processingBilling data (no PHI)USA
PostmarkTransactional email deliveryEmail addresses, notifications (no PHI)USA
Apple App StoreiOS app distributionApp metadata, user accountUSA
Google Play StoreAndroid app distributionApp metadata, user accountUSA
SectigoSSL/TLS certificate authorityDomain validation dataUSA / UK
DMARC DigestsEmail authentication monitoringDomain & email auth reports (no PHI)USA

This list is maintained as part of our Data Processing Agreement. We provide at least 30 days' prior written notice before engaging a new sub-processor.

Organisational Security

Security is a culture, not just a feature.

badge

Employee Security

All team members undergo background checks and mandatory security awareness training. Access follows the principle of least privilege and is reviewed regularly.

handshake

Vendor Management

Every sub-processor undergoes due diligence review before engagement. Contractual data protection obligations, regular reassessment and right-to-audit clauses are standard.

backup

Business Continuity

Disaster recovery plans, encrypted backups and uptime monitoring ensure service availability. Infrastructure spans multiple regions for geographic redundancy.

Documents & Resources

Everything you need for due diligence.

Your Data, Your Rules

Immediate deletion & granular control.

Audio retention

Deleted after note generation

Transcript storage

Short retention / user‑controlled

User deletion

Export & permanent erase at any time

Audit trails

Full activity logs for governance

Clinic Resources

Patient privacy notice for your practice.

Download our printable patient privacy leaflet to display in your waiting room or consultation area. It explains how AI documentation works, what happens to the recording, and reassures patients about their privacy.

description

Patient Privacy Notice — Printable Leaflet

Available in 6 languages. Designed for clinic walls and waiting rooms.

download English Français Español Português Italiano العربية
ClinixQM
Quality assured by ClinixQM
clinixqm.gacrux.ai open_in_new

Ready to secure your documentation workflow?

Assured by ClinixQM Quality Management Process